PT-2026-95234 · WordPress · Qi Addons For Elementor
CVE-2026-84902
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
King Addons for Elementor versions prior to 51.1.81
Description
An issue exists where the software fails to perform an object-level authorization check during the import of template content into a page. This allows users with contributor-level access or higher to overwrite the content of arbitrary posts and pages, including those belonging to administrators. Additionally, JavaScript can be injected via a widget setting that is output without escaping, leading to Stored Cross-Site Scripting (XSS), which is a vulnerability that allows an attacker to store malicious scripts on a server that are then executed in the browser of any user viewing the affected page.
Recommendations
Update to version 51.1.81 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Addons For Elementor